piątek, 5 września 2014

GetClouder domain takeover

GetClouder is cloud hosting service having bug bounty program. In Administration Panel we have some domain management tool for hosting our own domain names. After adding ANY domain - zone is configured on two DNS servers: nimbus.getclouder.com and cumulus.getclouder.com - even if we are not owner of the domain.

If you get NS records for getclouder.com domain, you'll see that it's hosted on same servers:

So my first try was trying to add getclouder.com domain - of course it failed. ;)

Then - I tried to search if GetClouder have any other interesting domains. Here's what I found:

In short - yes, they have other domains. One of interesting - clouder.us or getclouder.info are hosted on ns1.clev1.net and ns2.clev1.net. Now - just check the IP addresses of this servers:

zoczus@hell:~$ host ns1.clev1.net

ns1.clev1.net has address 181.224.128.6

zoczus@hell:~$ host ns2.clev1.net

ns2.clev1.net has address 198.20.77.76

zoczus@hell:~$ host nimbus.getclouder.com

nimbus.getclouder.com has address 181.224.128.6

zoczus@hell:~$ host cumulus.getclouder.com

cumulus.getclouder.com has address 198.20.77.76

So we have few other possibilities to check. I tried to add clev1.net, it failed - but adding ns1.clev1.net - not. :) Win?

Yup - it was deffinetly win.

zoczus@hell:~$ host wow.ns1.clev1.net

wow.ns1.clev1.net has address 1.2.3.4

zoczus@hell:~$ dig +trace ns1.clev1.net

; <<>> DiG 9.8.3-P1 <<>> +trace ns1.clev1.net

;; global options: +cmd

.85638INNSl.root-servers.net.

.85638INNSb.root-servers.net.

.85638INNSk.root-servers.net.

.85638INNSj.root-servers.net.

.85638INNSi.root-servers.net.

.85638INNSa.root-servers.net.

.85638INNSm.root-servers.net.

.85638INNSh.root-servers.net.

.85638INNSe.root-servers.net.

.85638INNSf.root-servers.net.

.85638INNSd.root-servers.net.

.85638INNSc.root-servers.net.

.85638INNSg.root-servers.net.

;; Received 241 bytes from 62.21.99.94#53(62.21.99.94) in 122 ms

net.172800INNSd.gtld-servers.net.

net.172800INNSb.gtld-servers.net.

net.172800INNSg.gtld-servers.net.

net.172800INNSe.gtld-servers.net.

net.172800INNSk.gtld-servers.net.

net.172800INNSl.gtld-servers.net.

net.172800INNSi.gtld-servers.net.

net.172800INNSf.gtld-servers.net.

net.172800INNSj.gtld-servers.net.

net.172800INNSm.gtld-servers.net.

net.172800INNSh.gtld-servers.net.

net.172800INNSc.gtld-servers.net.

net.172800INNSa.gtld-servers.net.

;; Received 488 bytes from 202.12.27.33#53(202.12.27.33) in 132 ms

clev1.net.172800INNSns1.clev1.net.

clev1.net.172800INNSns2.clev1.net.

;; Received 95 bytes from 192.55.83.30#53(192.55.83.30) in 167 ms

ns1.clev1.net.86400INA8.8.4.4

ns1.clev1.net.86400INA8.8.8.8

ns1.clev1.net.86400INNScumulus.getclouder.com.

ns1.clev1.net.86400INNSnimbus.getclouder.com.

;; Received 152 bytes from 181.224.128.6#53(181.224.128.6) in 174 ms

We have full control of ns1.clev1.net - so everyone asking for - let's say - clouder.us will got response about it's hosted on ns1.clev1.net (and ns2.clev1.net) which points to IP addresses controled by us.

The second vulnerability was ability to add root-servers.net zone.

After adding just 3 root servers (a,b,c), pointing it to IP with DNSChef on board, and waiting few minutes this is what I got:

As GetClouder told me - it was result of one tool for checking if customer's domains are still pointed to its nameservers.

I want to thank GetClouder security team for realy fast responses and the way how they did treat me as researcher. That was one of my best bounty experiences :)

8 komentarzy:

Softhof Best Web Hosting Pakistan UAE, Free Web Hosting and SEO Pakistan UAE, Affordable Search Engine Optimization. Domain registration services and Web Designing and Development. We are providing special web hosting packages with free domains only to customer’s in Pakistan. We have servers available in both Linux and Windows. We provide service 24/7 in a year.web hosting in Pakistan